<?php
defined('DCS_ROOT') or exit(header("HTTP/1.1 430 Not Forbidden"));

class uploads {
	function __construct (){
		//todo
		$this->url = getUrl();
		$action = $this->url['params']['1'];
		if(is_numeric($action)){
			$this->defaultAction();
		}elseif($action == 'editphotos'){
			$this->editPhotos();
		}else{
			exit('system error.');
		}
		exit();
	}

	function defaultAction(){
		$url = getUrl();
		$mid = $url['params']['1'];
		if(!is_numeric($mid)){
			exit('system error');
		}
		$user = getMember();
		if(empty($user)){
			exit('system error');
		}
		$uid = $user['uid'];

		if(!empty($_FILES['Filedata']['tmp_name'])){			
			require_once(CLASS_PATH."Class/Upload.class.php" );
			$upload = new Upload();
			$upload->config(array(
				'targetDir' => 'photos/',
				'saveType' => 2
			));
			$files = $upload->saveFiles('Filedata');
			$file_url = $files['0']['filenames'];
		}else{
			exit('2');
		}

		$sourFile = UPLOAD_PATH.'photos/'.$file_url;
		$targetFile = UPLOAD_PATH.'photos/thumb/'.$file_url;
		thumbs($sourFile,$targetFile,100,100);

		$db  = getDB();
		$time = time();
		$sql = "INSERT INTO movie_photo (mid,uid,filename,addtime,tmp) VALUES ('$mid','$uid','$file_url','$time','1')";
		$db->query($sql);

		$sql = "UPDATE movie SET photos = photos+1  WHERE id = '$mid' ";
		$db->query($sql);	

		exit('ok');
	}




}
?>